CVE-2026-88819

Summary

In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.

Affected Software

VendorProductVersion RangeStatus
Eclipse FoundationEclipse Data Plane Corea6f7d4cc0093931287c349e1e546ad2932c08e8d < 882fe22db42bc67abfd0304c4cdb141b762c35d1affected
Eclipse FoundationEclipse Data Plane Core0.1.0 <= 0.1.3affected

Weaknesses

  • CWE-290: CWE-290 Authentication bypass by spoofing
  • CWE-345: CWE-345 Insufficient Verification of Data Authenticity

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References